Secretary of State Marco Rubio announced Thursday that the United States will deny or revoke visas for foreign nationals responsible for cyberscams and sextortion — and, in some cases, their immediate family members — using a Cold War-era immigration provision that requires no criminal conviction, no public disclosure of who has been targeted, and no stated evidentiary standard. The cybercrime visa restriction policy, announced on the final day of Rubio’s trip to Manila for the Association of Southeast Asian Nations ministerial meetings, marks the first time the Trump administration has deployed immigration law as a standalone tool against foreign cybercriminals.
The policy sits on top of an enforcement campaign that has already recovered more than $800 million in cryptocurrency stolen from American fraud victims since November 2025 — while FBI Director Kash Patel conducted parallel meetings with Southeast Asian leaders the same week, and the Justice Department’s Scam Center Strike Force filed five new civil forfeiture complaints just two days earlier seeking more than $25 million linked to pig-butchering operations in Cambodia and Myanmar.
$21 Billion a Year and Rising: What Cyberscams Are Costing Americans
The scale of the threat the policy is designed to address is not subtle. The FBI’s Internet Crime Complaint Center logged 1,008,597 complaints in 2025 — the first time in the agency’s 25-year history that annual complaints topped one million — with total reported losses of $20.877 billion, a 26% jump from the prior year’s record. Investment fraud, of which pig-butchering cryptocurrency scams are the dominant form, drove $8.65 billion of those losses. Americans over 60 reported $7.748 billion in losses — up 59% from 2024 — with investment scams as the primary driver.
The State Department’s statement went further, attributing at least $10 billion in losses in 2024 alone specifically to Chinese transnational criminal organizations orchestrating pig-butchering investment scams. Those groups also run the human trafficking operations that supply labor to Southeast Asian scam compounds in Cambodia, Myanmar, and Laos — where, according to the United Nations Human Rights Office, hundreds of thousands of people are held against their will and forced to run the emotional grooming conversations that lure victims into fraudulent crypto investments.
American children face a separate and deliberately targeted threat. The State Department specifically named overseas sextortion rings — operations that manipulate minors into sharing compromising images, then use them as leverage to extort money — as a co-equal target of the new policy.
How the Legal Mechanism Works: What It Does and Does Not Require
The policy operates under Section 212(a)(3)(C) of the Immigration and Nationality Act, a provision dating to the McCarran-Walter Act of 1952, which grants the Secretary of State authority to deny or revoke a visa whenever a foreign national’s entry could pose “potentially serious adverse foreign policy consequences” for the United States. The phrase is deliberately broad: it was written during the Cold War to exclude communists and other political figures the State Department judged threatening, and it has been applied to a wide range of targets in the decades since.
What §212(a)(3)(C) does not require is a criminal conviction — or even a formal charge. Consular officers can deny a visa based on government records and determinations whose underlying basis may not be disclosed to the applicant. There is no public registry of who has been targeted. No published evidentiary threshold governs which individuals qualify. A denial under this provision is difficult to appeal precisely because the grounds may remain confidential.
That opacity is a feature in the law’s original design — it preserves the State Department’s foreign-policy flexibility — but it is also the core of the due-process concern critics have raised. The Trump administration has invoked the same provision this year in other policy domains, including against individuals alleged to be associated with far-left groups, those accused of enabling Cuban state-sponsored labor programs, and people said to be undermining regional stability in the Western Hemisphere. Civil liberties advocates have argued in several of those contexts that the provision’s opacity creates a mechanism for politically motivated exclusions that targets cannot effectively challenge.
The new cybercrime policy extends the mechanism to the families of alleged perpetrators. “Immediate family members of individuals engaged in such illicit activities may also be subjected to visa restrictions,” Rubio’s statement read. Family members have no independent obligation to apply for a visa review, no published standard to contest, and no disclosed list to consult to find out whether they have been flagged. The State Department did not indicate what, if any, nexus a family member would need to have to criminal activity before restrictions apply.
What “Pig Butchering” Is, and How the Criminal Infrastructure Behind It Operates
A pig-butchering scam — the term comes from the Chinese metaphor sha zhu pan, meaning “killing pig plate,” referring to the practice of fattening victims before slaughter — combines social engineering with cryptocurrency investment fraud. Criminals establish contact via social media, dating apps, or text messages, invest weeks or months cultivating a fake romantic or social relationship, and then introduce the victim to a fraudulent cryptocurrency trading platform that the criminals control. Initial “profits” are simulated to build confidence; once the victim has transferred substantial funds, the platform disappears along with the money.
The criminal operations behind these scams are not lone actors working from home. They are industrial-scale enterprises. The Huione Group — a Cambodia-based conglomerate whose FinCEN designated as “a primary money laundering concern” in 2025 — ran Huione Guarantee, a Telegram-based marketplace where vendors openly sold stolen identity data, money mule networks, tools for running scam operations, and services for converting stolen cryptocurrency into legitimate banking-sector funds. Blockchain analytics firm Elliptic documented that Huione Guarantee processed more than $27 billion in crypto transactions since its launch, making it the largest illicit online marketplace ever recorded.
In June 2026, the Justice Department seized the cloud computing account that hosted the backend infrastructure for those subsidiaries, as part of Operation Riptide — an ongoing FBI campaign formally launched June 9, 2026, implementing EO 14390. “Today’s seizure strikes a blow against one of the world’s most prolific criminal marketplaces,” said Assistant Attorney General A. Tysen Duva.
That action did not shut down the broader ecosystem. Elliptic reports that more than 30 active guarantee marketplaces operate today, with Xinbi Guarantee now leading the market and having received more than $24 billion in cryptocurrency transactions to date. The infrastructure disrupted by Operation Riptide has migrated, not disappeared.
Expert Reaction: Conditional Approval and Caveats
The announcement drew measured support from cybersecurity and policy experts, with consistent calls for precision in implementation.
Betsy Cooper, founding director of the Aspen Policy Academy, called the step a positive development under a specific condition. “Scamming people is a growing global enterprise, and it is a laudable goal to penalize those who scam and defraud people since they so rarely suffer consequences for their actions,” she said in a statement. “So long as the new visa controls are used narrowly and deployed only against verified scammers and fraudsters, this is a positive step toward combatting cyber-enabled crime,” Cooper told CyberScoop.
The nonprofit FightCyberCrime.org endorsed the restrictions while pressing for parallel investment in victim services. “Cryptocurrency investment scams, romance scams, and sextortion cause devastating financial and emotional harm to victims. Meaningful disruption of these transnational criminal networks is an essential part of the response,” the organization said in a statement to CyberScoop. “At the same time, we must invest more in victim support, prevention, and recovery resources. Accountability is critical, but ensuring victims have access to trauma-informed support and resources is equally important.”
The deterrence question remains open. Some cybersecurity analysts have pointed out that overseas criminals operating from Myanmar, Cambodia, or Laos may have little immediate interest in U.S. visa access — making the restriction’s near-term operational impact uncertain. Proponents counter that visa restrictions create long-term costs for cybercrime operators who value international travel for business purposes — and signal to governments in the region that tolerating scam compound operators carries diplomatic consequences.
Where This Sits in a Broader Enforcement Push
Thursday’s visa announcement is one piece of an enforcement posture the administration has built over 2026. The backstory:
On March 6, 2026, President Trump signed Executive Order 14390, “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens,” directing federal agencies to develop coordinated action plans and explicitly naming visa restrictions as one of the available tools alongside sanctions, criminal prosecutions, asset seizures, and extradition requests.
Operation Riptide, the FBI’s sustained enforcement response, launched June 9, 2026. Its first major action was the international takedown of First VPN Service, used by ransomware groups to conceal operations. The Huione Group seizure followed on June 23, 2026. On July 21, 2026, the Scam Center Strike Force — a separate initiative launched in November 2025 by U.S. Attorney Jeanine Ferris Pirro for the District of Columbia — filed five new civil forfeiture complaints targeting more than $25 million in cryptocurrency tied to pig-butchering operations, part of more than $800 million the Strike Force has recovered since its launch.
The timing carries a geopolitical dimension as well. Rubio made the announcement on the same trip in which he met with Chinese Foreign Minister Wang Yi on the ASEAN sidelines, with reports indicating an anticipated Trump-Xi summit on the horizon. The administration has consistently framed Chinese TCOs as the primary architecture behind pig-butchering fraud — while separately noting that Chinese government-linked hacking groups such as Salt Typhoon and Volt Typhoon have conducted distinct state-sponsored operations against U.S. telecom providers and critical infrastructure. The criminal TCO dimension and the state-espionage dimension involve different actors and different policy responses; the visa restriction policy addresses only the former.
What the Policy Does Not Yet Answer
Rubio’s statement commits the administration to act but does not resolve several questions that will govern the policy’s real-world reach.
No evidentiary threshold has been published. Unlike the sanctions regime administered by the Treasury’s Office of Foreign Assets Control — which publishes a named SDN list and requires that designations meet a defined evidentiary standard — §212(a)(3)(C) visa restrictions can be applied with no public record. Someone denied a visa under this policy may not be told why.
No first restrictions have been publicly announced. The State Department has not indicated when the first specific individuals will be targeted, what standards govern the “complicit in” language used in the policy, or what relationship family members need to have with criminal activity before they are affected.
The successor marketplace problem persists. Even as enforcement actions have dismantled specific criminal infrastructure — Huione Guarantee, First VPN Service, multiple ransomware hosting services — blockchain analytics firms document that more than 30 active successor platforms have filled the gap. Visa restrictions against named individuals do not address the structural infrastructure that allows new operators to replace those who are sanctioned, arrested, or extradited.
Frequently Asked Questions
What is a pig-butchering scam, and why is it the focus of this policy?
A pig-butchering scam is a form of romance-investment fraud in which criminals establish fake online relationships with targets over weeks or months, build trust, then persuade them to invest in fraudulent cryptocurrency platforms the criminals control. Once a victim transfers significant funds, the platform vanishes. The FBI’s IC3 logged more than $8.65 billion in losses from investment fraud in 2025, of which pig-butchering scams are the primary driver. The State Department attributes at least $10 billion in 2024 pig-butchering losses specifically to Chinese transnational criminal organizations. Visa restrictions target the human operators behind these networks specifically because criminal prosecution of overseas suspects is slow, extradition is inconsistent, and many operators have previously faced little personal consequence.
Can the U.S. deny a visa to a cybercriminal’s family member who has never committed a crime?
Yes, under this policy. Section 212(a)(3)(C) of the Immigration and Nationality Act does not require a criminal conviction to support a visa denial — it requires only a government determination that someone’s entry poses “potentially serious adverse foreign policy consequences.” The Rubio announcement explicitly states that “immediate family members of individuals engaged in such illicit activities may also be subjected to visa restrictions.” No published standard governs what nexus a family member must have to criminal activity, no public list of targeted individuals exists, and determinations may be kept confidential. This is the same legal structure that has drawn civil liberties criticism in other contexts where the provision has been applied.
Does this policy make it harder for overseas cybercriminals to operate their scams?
In the short term, the direct operational impact is uncertain. The most capable cybercrime operators work from Myanmar, Cambodia, and Laos in compounds staffed partly by trafficked workers — and many of those individuals may not have U.S. visa applications in their near-term plans. The policy’s deterrence value is more plausibly aimed at the organizers and financiers of criminal networks who do value international travel for business and personal purposes, and at foreign governments that have tolerated scam center operations within their borders. Rubio held specific talks with Cambodia’s foreign minister about scam compounds during the same ASEAN trip. The criminal infrastructure itself — the successor marketplaces, the money-laundering networks — requires enforcement actions beyond visa restrictions to disrupt.
What should Americans do if they believe they have been targeted by a pig-butchering or sextortion scam?
Report to the FBI’s Internet Crime Complaint Center at ic3.gov, regardless of how much money was lost or whether a transfer was completed. If a minor is being targeted for sextortion, the National Center for Missing and Exploited Children’s CyberTipline at cybertipline.org accepts reports. Victims should not send additional money in response to recovery offers — recovery fraud, in which scammers pose as helpers who can retrieve lost funds, is one of the fastest-growing variants and specifically targets people who have already been victimized, as documented in the DOJ Scam Center Strike Force’s most recent filings.
Click Here For The Original Source.
